ZeroHour

CVE-2018-20768

CVSS 3.0
9.8 critical
EPSS
1%p67
Published
()
Modified
Description

An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. An attacker can execute PHP code by leveraging a writable file.

Vendors
xerox
Products
workcentre 3655i firmware, workcentre 3655 firmware, workcentre 5890i firmware, workcentre 5865i firmware, workcentre 5875i firmware, workcentre 5845 firmware, workcentre 5865 firmware, workcentre 5875 firmware, workcentre 5890 firmware, workcentre 5900 firmware, workcentre 5900i firmware, workcentre 6655 firmware
Weakness
CWE-94
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.